BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m...
Vulnerability Description
BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive information, such as configuration information via (1) /btvoyager_getconfig.sh, PPP credentials via (2) btvoyager_getpppcreds.sh, and decode configuration credentials via (3) btvoyager_decoder.c.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3561
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/489009/100/0/threaded
- http://www.gnucitizen.org/projects/router-hacking-challenge/
- http://www.gnucitizen.org/blog/holes-in-embedded-devices-authentication-bypass-pt-3/
- http://www.securityfocus.com/bid/19057
- http://www.securityfocus.com/archive/1/440405/100/0/threaded
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047733.html
- http://www.vupen.com/english/advisories/2006/2734
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27652
- http://secunia.com/advisories/20982
- http://ikwt.dyndns.org/projects/btvoyager-getconfig.txt
More from bt
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.